10,000 Firms are the target of a phishing campaign that sidesteps multi-factor authentication.
Microsoft has released information about a massive phishing effort that was able to defeat Multi-Factor Authentication (MFA) defenses in addition to attempting to obtain the credentials of targeted organizations. Attackers pretended to be Office 365 login pages that sought MFA codes via reverse-proxy AiTM (Attacker-in-the-Middle) sites, and then used those codes to connect into…